Sus.Behav
Sus.Behav Description
Sus.Behav is a malware that installs itself onto a computer under deceptive pretences, infiltrating a system without user knowledge or permission. Officially categorized as a file, displaying suspicious behavior, Sus.Behav should not be trusted. Sus.Behav may typically be downloaded unknowingly from malicious websites, freeware and shareware, and peer-to-peer networks. Sus.Behav can cause registry files to go missing, corrupt files to re-open after being erased, unwanted web browser components, changes in Internet settings and decreased system speeds.
Type: Malware
How Can You Detect Sus.Behav?
Sus.Behav has typically the following processes in memory:
- EntriqMediaServer.exe
- opnonkhe.dll
- FGSHEL~1.DLL
- CarboniteSetupLitePBPreInstaller.exe
- fpfstb.dll
- DWRCS.EXE
- alt.exe.exe
- cbXPiFwT.dll
- ERCUtil.dll
- ccleaner.exe
- CarbonitePreinstaller.exe
- xfire.exe
- SpySweeperUI.exe
- tuvVLcay.dll
- rqRiiHXQ.dll
- av2009.exe
- tbaction.exe
Sus.Behav creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\opnonkhe
- RUNNING PROGRAM\EXPLORER.EXE
- HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 29247207685934936530823877733220
- RUNNING PROGRAM\DWRCS.EXE
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ TBAction
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ PromoReg
- RUNNING PROGRAM\winlogon.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ CarboniteSetupLite
- RUNNING PROGRAM\xfire.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\ AppInit_DLLs
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SpySweeper
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\tuvVLcay
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\__c00135A8
- HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ccleaner
- RUNNING PROGRAM\EntriqMediaServer.exe
Important Article Disclaimer

English 
Deutsch
Español
Français
Portuguese
Sus.Behav 










